IN THE UNITED STATES ARMY 
FIRST JUDICIAL CIRCUIT 



UNITED STATES 




v. 



RULING: DEFENSE MOTION: 
DISMISS SPECIFICATIONS 13 
AND 14 OF CHARGE II - FAIL 
TO STATE AN OFFENSE 



DATED: 8 June 2012 



Henderson Hall, Fort Myer, VA 22211 ) 

Defense moves the Court to dismiss Specifications 13 and 14 of Charge II for failure to 
state an offense because the Government has failed to allege the Accused's conduct exceeded 
unauthorized access within the meaning of 18 U.S.C. Section 1030(a)(1). Government opposes. 
After considering the pleadings, evidence presented, and argument of counsel, the Court finds 
and concludes the following: 

Factual Findings: 

1. Specifications 13 and 14 of Charge II charge PFC Manning with violating 18 U.S.C. Section 
1030(a)(1) and Article 134, UCMJ. 

2. Specification 1 3 of Charge II alleges that the accused: 



did, at or near Contingency Operating Station Hammer, Iraq, 
between on or about 28 March 2010 and on or about 27 May 2010, 
having knowingly exceeded authorized access on a Secret Internet 
Protocol Router Network computer, and by means of such conduct 
having obtained information that has been determined by the 
United States government pursuant to an Executive Order or 
statute to require protection against unauthorized disclosure for 
reasons of national defense or foreign relations, to wit: more than 
seventy-five classified United States Department of State cables, 
willfully communicate, deliver, transmit, or cause to be 
communicated, delivered, or transmitted the said information, to a 
person not entitled to receive it, with reason to believe that such 
information so obtained could be used to the injury of the United 
States, or to the advantage of any foreign nation, in violation of 18 
U.S. Code Section 1030(a)(1) such conduct being prejudicial to 
good order and discipline in the armed forces and being of a nature 
to bring discredit upon the armed forces. 



3. Specification 14 of the same charge alleges that the accused: 



APPELLATE F.VHlRl TCLxxM t \C 
Pag e \ of Pagc(s) ^ 



1 



did, at or near Contingency Operating Station Hammer, Iraq, 
between on or about 15 February 2010 and on or about 18 
February 2010, having knowingly exceeded authorized access on a 
Secret Internet Protocol Router Network Computer, and by means 
of such conduct having obtained that has been determined by the 
United States government pursuant to an Executive Order or 
statute to require protection against unauthorized disclosure for 
reasons of national defense or foreign relations, to wit: a classified 
Department of State cable titled "Reykjavik- 13", willfully 
communicate, deliver, transmit, or cause to be communicated, 
delivered, or transmitted the said information, to a person not 
entitled to receive it, with reason to believe that such information 
so obtained could be used to the injury of the United States, or to 
the advantage of any foreign nation, in violation of 18 U.S. Code 
Section 1030(a)(1) such conduct being prejudicial to good order 
and dis cipline in the armed forces and being of a nature to bring 
discredit upon the armed forces. 

3. Defense avers that the Government theory at trial will be either that: (1) PFC Manning 
exceeded authorized access when he allegedly accessed information for an improper purpose (to 
give it to someone not entitled to receive it); or (2) that PFC Manning exceeded authorized 
access when he allegedly accessed, stored, and disclosed information in contravention of the 
Army's acceptable use policy (AUP). The Government asserted during oral argument that it will 
be presenting evidence in addition to the (AUP) to prove that the accused exceeded authorized 
access. 

4. During the Article 32 Investigation, Special Agent ■ I from the U.S. Army 
Computer Crimes Investigative Unit testified that he examined the two Secret Internet 
Protocol Router Network (SIPRNET) computers used by the accused from approximately 
October 2009 through May 2010. (Gov't Enclosure 1, pp. 125-7). Special Agent — 
testified when logging into both computers, the user is presented with a warning banner. 
Id at 134-5. 

5. The warning banner states as follows; 

You are accessing a U.S. Government (USG) Information System 
(IS) that is provided for USG-authorized use only. By using this 
IS (which includes any device attached to this IS), you consent to 
the following conditions: The USG routinely intercepts and 
monitors communications on this IS for purposes including, but 
not limited to, penetration testing, COMSEC, monitoring, network 
operations and defense, personnel misconduct (PM), law 
enforcement (LE), and counterintelligence investigations. At any 
time, the USG may inspect and seize data stored on this IS. 
Communications using, or data stored on, this IS are not private, 
are subject to routine monitoring, interception and search, and may 



2 



be disclosed or used for any USG authorized purpose. This IS 
includes security measures (e.g. authentication and access controls) 
to protect USG-interests not for your personal benefit or privacy. 
Notwithstanding the above, using this IS does not constitute 
consent to PM, LE, or CI investigative searching or monitoring of 
the contect [sic] of priviledged [sic] communications, or work 
product, related to personal representation or services by attorneys, 
psychotherapists, or clergy, and their assistants. Such 
communications and w T ork product are private and confidential. 
See User Agreement or details. 

(Gov't Enclosure 2.) 

6. In January 201 1 , Special Agent 85 I f rom U.S. Army Computer Crime 
Investigative Unit interviewed Captain (CPT) | |. from Headquarters and 
Headquarters Company, 2 nd Brigade Combat Team, 10 Mountain Division, who was the 
Assistant S~6 Officer during the time the accused was stationed in Iraq. (Gov't Enclosure 
5, p. 1) CPT ii)IOI(?jM stated that a signed user agreement for each user was required to 
access SIPRNET; however, he could not locate a copy of accused's signed user 
agreement. Id. 

7. Defense does not contest that specifications 1 3 and 14 allege every element of the offense 
charged, 18 U.S.C Section 1030(a)(1) and Article 1 34 UCMJ. Defense challenges the theory 
underlying the specification as deficient Such a challenge has been styled a 'Tailure to state an 
offense" in Federal Courts under Federal Rule of Criminal Procedure 12 and, where the 
Government theory is undisputed, the Court can address and dismiss the charge prior to trial. 
See US. v. Nosal, 2012 WL 1176119 (9 th Cir. 2012). 

The Law: Failure to State an Offense. 

1 . The military is a notice pleading jurisdiction. A charge and its specification is sufficient if it 
(1) contains the elements of the offense charged and fairly informs an accused of the charge 
against which he must defend; and (2) enables the accused to plead an acquittal or conviction in 
bar of future prosecutions for the same offense. In reviewing the adequacy of a specification, the 
analysis is limited to the language as it appears in the specification, which must expressly allege 
the elements of the offense or do so by necessary implication. U.S. v. King, 71 M.J. 50, fh 2, 
(C.A.A.F. 2012), quoting U.S. v. Foster, 70 M.J. 225, 229 (C.A.A.F. 2011) and U.S. v. Fleig, 16 
CM A. 444, 445 (1966) (looking '^within the confines of the specification"). A motion to 
dismiss for failure to state an offense is a challenge to the adequacy of a specification and 
whether the specification "alleges, either expressly or by implication, every element of the 
offense, so as to give the accused notice and protection against double jeopardy." United States 
v. Amazaki, 67 MJ. 666, 669, 670 n.8 (A. Ct Crim. App. 2009) (quoting United States v. 
Crafter, 64 M.J. 209, 21 1 (CA.A.F. 2006)). 

The Law: The Computer Fraud and Abuse Act (CFAA), 18 U.S.C § 1030(a)(1). 

1 . An accused violates the Computer Fraud and Abuse Act (CFAA) when the accused 



3 



knowingly accessed a computer without authorization or exceeding 
authorized access, and by means of such conduct having obtained 
information that has been determined by the United States 
Government pursuant to an Executive order or statute to require 
protection against unauthorized disclosure for reasons of national 
defense or foreign relations, or any restricted data, as defined in 
paragraph y. of section 1 1 of the Atomic Energy Act of 1954, with 
reason to believe that such information so obtained could be used 
to the injury of the United States, or to the advantage of any 
foreign nation willfully communicates, delivers, transmits, or 
causes to be communicated, delivered, or transmitted, or attempts 
to communicate, deliver, transmit or cause to be communicated, 
delivered, or transmitted the same to any person not entitled to 
receive it, or willfully retains the same and fails to deliver it to the 
officer or employee of the United States entitled to receive it. 1 8 
U.S.C. §1030(a)(l)(emphasis added) . 

2. 18 U.S.C. § 1030(e)(6) defines the phrase "exceeds authorized access" as "to access a 
computer with authorization and to use such access to obtain or alter information in the 
computer that the accesser is not entitled so to obtain or alter." 

Analysis: Statutory Interpretation 

1. The crux of the Defense motion is the interpretation of the "exceeds authorized access" 
language in the CF AA. Defense argues that the Government failed to allege that he "exceeded 
authorized access" within the meaning CFAA because he was authorized to access the SIPRNET 
and entitled to access the classified information in question. The Government has alleged in the 
specification that the accused "exceeded authorized access". The Government further avers that 
it will prove the accused "exceeded authorized access" by the AUP and by other evidence. 

2. In United States v. Starr, 51 M.J. 528, 532 (A.F. Ct. Crim. App. 1999), the Air Force Court of 
Criminal Appeals provided a roadmap to resolving the legal meaning of a statute: 

It is the function of the legislature to make the laws and the duty of 
judges to interpret them. 2A Norman J. Singer, Sutherland 
Statutory Construction § 45.03 (4th ed. 1984). Judges should 
interpret a statute so as to carry out the will of the legislature. 
United States v. Dickenson, 20 C.M.R. 154, 165 (CM. A. 1955). 
Otherwise, they violate the principle of the separation of powers. 
Singer, supra, § 45.05. "If the words used in the statute convey a 
clear and definite meaning, a court has no right to look for or to 
impose a different meaning." Dickenson, 20 C.M.R. at 165. Thus, 
in interpreting a statute, we employ the following process: (1) Give 
the operative terms of the statute their ordinary meaning; if the 
terms are unambiguous, the inquiry is over; (2) If the operative 



4 



terms of the statute are ambiguous, then we examine the purpose of 
the statute as well as its legislative history; and (3) If a reasonable 
ambiguity still exists, then we apply the rule of lenity and resolve 
the ambiguity in favor of the accused. 

CFAA: Ordinary Meaning of the Statute 

As discussed in further detail below, the term "exceeds authorized access" has been subject to 
differing interpretations among the U.S. Circuit Courts of Appeals thereby indicating that the 
statutory language is not clear and definite. Compare Nosal III, 2012 W.L. 1176119 with United 
States v. John, 597 F.3d 263 (5th Cir. 2010) and United States v. Rodriguez, 628 F.3d 1258 (11th 
Cir. 2007). Therefore, because the ordinary meaning of the operative language is ambiguous, the 
Court must look to the purpose of the statute and statutory history. Starr, 51 M.J. at 532. 

CFAA: Legislative History. 

1. The CFAA was originally enacted in 1984. Act of Oct. 12, 1984, Pub. L. No. 98-473, §§ 
2101-2103, 98 Stat. 1837, 2190-92. In its original version, Section 1030(a)(1) punished anyone 
who 

knowingly accesses a computer without authorization, or having 
accessed a computer with authorization, uses the opportunity such 
access provides for purposes to which such authorization does not 
extend, and by means of such conduct obtains information that has 
been determined by the United States Government ... to require 
protection against unauthorized disclosure for reasons of national 
defense or foreign relations . . . with the intent or reason to believe 
that such information so obtained is to be used to the injury of the 
United States, or to the advantage of any foreign nation. 

Id. § 2102(a), 98 Stat. 2190 (emphasis supplied). 

2. Two years later in 1986, Congress replaced the terms "or having accessed a computer with 
authorization, uses the opportunity such access provides for purposes to which such 
authorization does not extend" with the terms "or exceeds authorized access." Computer Fraud 
and Abuse Act of 1986, Pub. L. No. 99-474, § 2(c), 100 Stat. 1213. As the Senate Report for the 
1986 bill explained: 

Section 2(c) [of the 1986 bill] substitutes the phrase 'exceeds 
authorized access' for the more cumbersome phrase in present 18 
U.S.C. § 1030(a)(1) and (2), 'or having accessed a computer with 
authorization, uses the opportunity such access provides for 
purposes to which such authorization does not extend'. The 
Committee intends this change to simplify the language in 18 
U.S.C. § 1030(a)(1) and (2), and the phrase 'exceeds authorized 
access' is defined separately in Section 2(g) of the bill. 



5 



S. Rep. No. 99-432, pt. 3, reprinted in 1986 U.S.C.C.A.N. 2479, 2486. 



3. Additionally, Congress added to Section 1030 the definition of "exceeds authorized access" 
that is presently codified at § 1030(e)(6). Id. § 2(g)(4); see 18 U.S.C. § 1030(e)(6). However, in 
its attempt to simplify the language, Congress changed the scope of the statute: 

Further, the legislative purpose and history supports the plain 
meaning of the statute. Congress enacted the CFAA to deter "the 
criminal element from abusing computer technology in future 
frauds." H.R.Rep. No. 98 894, at 4 (1984), reprinted in 1984 
U.S.C.C.A.N. 3689, 3690. As originally enacted, the CFAA 
applied to a person who (1) knowingly accessed without 
authorization or (2) "having accessed a computer with 
authorization, uses the opportunity such access provides for 
purposes to which such authorization does not extend." Pub.L. No. 
98 473, § 2102, 98 Stat. 2190, 2190 91 (1984). Congress 
amended the statute by replacing the latter means of access with 
the phrase "exceeds authorized access." See Pub.L. No. 99-474, § 
2,100 Stat. 1213, 1213 (1986). The stated reason for the 
amendment was to simplify the language in 18 U.S.C. 1030(a)(1) 
and (2). 

4. In 1996, Congress amended 18 U.S.C. § 1030(a)(1) and clarified the differences 
between the CFAA and federal espionage statutes: 

Although there is considerable overlap between 18 U.S.C. [§] 
793(e) and [§] 1030(a)(1), as amended by the Nil Protection Act, 
the two statutes would not reach exactly the same conduct. [§] 
1030(a)(1) would target those persons who deliberately break into 
a computer to obtain properly classified Government secrets then 
try to peddle those secrets to others, including foreign 
governments. In other words, unlike existing espionage laws 
prohibiting the theft and peddling of Government secrets to foreign 
agents, [§] 1030(a)(1) would require proof that the individual 
knowingly used a computer without authority, or in excess of 
authority, for the purpose of obtaining classified information. In 
this sense then, it is the use of the computer which is being 
proscribed, not the unauthorized possession of, access to, or 
control over the classified information itself. 

5. Rep. No. 104-357 at 6-6 (1996) (emphasis added). 

5. Therefore, an analysis of the legislative history of the CFAA and the phrase "exceeds 
authorized access" reveals that the statute is not meant to punish those who use a computer for an 
improper purpose or in violation the governing terms of use, but rather the statute is designed to 



6 



criminalize electronic trespassers and computer hackers. See Int'l Ass'n of Machinists & 
Aerospace Workers, 390 F. Supp. 2d at 495 (quoting Sherman & Co. v. Salton Maxim 
Housewares, Inc., 94 F. Supp. 2d 817, 820 (E.D. Mich. 2000)). 

CFAA: Case Law and Conflict Among the Federal Circuits. 

1. In Nosal III, at 856, the appellant convinced his former co-workers at his previous firm, 
Korn/Ferry, to help him establish a competing business. The former co-workers used their 
Korn/Ferry log-in credentials to download information from a confidential database. They then 
passed this information to the appellant. The former co-workers "were authorized to access the 
database, but Korn/Ferry had a policy that forbade disclosing confidential information." The 
Defendant was charged, inter alia, with violations of 18 U.S.C. § 1030(a)(4), for aiding and 
abetting the Korn/Ferry employees in "exceeding their] authorized access" with intent to 
defraud." The appellant filed a motion to dismiss the CFAA charges, "arguing that the statute 
targets only hackers, not individuals who access a computer with authorization but then misuse 
information they obtain by means of such access. Id. 

2. The Court, in Nosal III at 857, agreed with the appellant's argument and disagreed with the 
prosecution's attempt to make the CFAA into "an expansive misappropriation statute" when it 
was originally was created as "an anti-hacking statute." To support its conclusion, the Nosal III 
Court cited the legislative purpose of the CFAA: 

Congress enacted the CFAA in 1984 primarily to address the 
growing problem of computer hacking, recognizing that, "[i]n 
intentionally trespassing into someone else's computer files, the 
offender obtains at the very least information as to how to break 
into that computer system." S.Rep. No. 99 432, at 9 (1986), 1986 
U.S.CC.A.N. 2479, 2487 (Conf. Rep.). Id. at 858. 

3. The Nosal III Court, in the end, held that the terms "'exceed authorized access' in the CFAA 
[and as defined by 18 U.S.C. § 1030(e)(6)] does not extend to violations of use restrictions." Id. 
at 863. Nosal III defines "exceeds unauthorized access" to apply to inside hackers or 
individuals whose initial access to a computer is authorized but who accesses unauthorized 
information or files. 

4. The Nosal ///Court, at 862, also acknowledged that its ruling differed from previous 
decisions made by other circuits namely United States v. John, 597 F.3d 263 (5th Cir. 2010) 
("Exceeds authorized access" occurred when the appellant violated her employer's official 
policy by misusing the company's internal computer when she properly accessed the computer 
system and customer account information contained in it, but provided the information to others 
who were able to incur fraudulent charges.) and United States v. Rodriguez, 628 F.3d 1258 (11th 
Cir. 2007)("Exceeds authorized access" occurred when the appellant violated his agency's policy 
of only obtaining information from its databases for official reasons by properly accessing the 
agency's computer system, but obtaining personal information from seventeen different 
individuals for personal reasons.) However, the Nosal ///Court reasoned that its sister circuits 
incorrectly looked at the culpable actions of the appellants and did not consider the negative 



7 



effects of expanding the definition of "exceeds authorized access" to include "violations of 
corporate computer use restrictions or violations of a duty of loyalty." 

5. Other court decisions support the Nosal III Court's narrow view of "exceeds authorized 
access." See Orbit One Commc'ns, Inc. v. Numerex Corp., 692 F.Supp.2d 373, 385 
(S.D.N. Y.2010); United States v. Aleynikov, 737 F. Supp. 2d 173, 192 (S.D.N. Y. 2010); 
Diamond Power Int% Inc. v. Davidson, 540 F.Supp.2d 1322, 1343 (N.D.Ga.2007); Shamrock 
Foods Co. v. Cast, 535 F.Supp.2d 962, 965 (D.Ariz.2008); Int'l Ass'n of Machinists & Aerospace 
Workers v. Werner-Masuda, 390 F.Supp.2d 479, 499 (D.Md.2005) . 

Rule of Lenity. 

1. When construing ambiguous criminal statutes, military courts have consistently applied the 
rule of lenity. See United States v. Schelin, 15 M.J. 218, 220 (C.M.A. 1983); United States v. 
Carlwright, 13 M.J. 174, 176 & n.4 (C.M.A. 1982); United States v. Inthavong, 48 M.J. 628, 630 
(A. Ct. Crim. App. 1998). "[T]he rule of lenity, which is rooted in considerations of notice, 
requires courts to limit the reach of criminal statutes to the clear import of their text and construe 
any ambiguity against the government." United States v. Romm, 455 F.3d 990, 1001 (9th Cir. 
2006). 

2. When applying the Rule of Lenity in the CFAA context, the Nosal III Court stated at 863: 

If Congress wants to incorporate misappropriation liability into the 
CFAA, it must speak more clearly. The rule of lenity requires 
"penal laws ... to be construed strictly." United States v. 
Wiltberger, 18 U.S. (5 Wheat.) 76, 95, 5 L.Ed. 37 (1820). 
"[W]hen choice has to be made between two readings of what 
conduct Congress has made a crime, it is appropriate, before we 
choose the harsher alternative, to require that Congress should 
have spoken in language that is clear and definite." Jones [v. 
United States], 529 U.S. [848,] 858, 120 S.Ct. 1904 [(2000)] 
(internal quotation marks and citation omitted)... This narrower 
interpretation is also a more sensible reading of the text and 
legislative history of a statute whose general purpose is to punish 
hacking the circumvention of technological access barriers - not 
misappropriation of trade secrets a subject Congress has dealt 
with elsewhere .... Therefore, we hold that "exceeds authorized 
access" in the CFAA is limited to violations of restrictions on 
access to information, and not restrictions on its use. 

Conclusions of Law: Failure to State an Offense. 

1. The language of Specifications 13 and 14 of Charge II includes all of the elements of the 
offense, fairly informs the accused of the charge against which he must defend, and protects the 
accused against double jeopardy. See King, at 51, fn 2; Fosler, at 229; Fleig, at 445. 



8 



2. Federal cases dismissing charges before evidence is presented do so under Federal Rule of 
Criminal Procedure 12. This court has the power to do the same under R.C.M. 907(b)(1). 
Whether the Court should dismiss the specifications before presentation of the evidence depends 
on whether the issue is capable of resolution without trial on the issue of guilt. In this case, the 
Government stated in oral argument that it would present evidence in addition to the AUP. The 
Court does not find that the issue is capable of resolution prior to presentation of the evidence. 
This issue is appropriately decided after presentation of the evidence either as a motion for a 
finding of not guilty under R.C.M. 917 or a motion for a finding that the evidence is not legally 
sufficient. King, 71 M.J. 50; U.S. v. Griffith, 27 M.J. 42 (C.M.A. 1988). 

3. The language of the specifications states an offense. 
Conclusions of Law: CFAA. 

1 . Applying the Rule of Lenity, the Court shall adopt the narrow meaning of "exceeds 
authorized access" under the CFAA and instruct the fact finder that the term "exceeds authorized 
access" is limited to violations of restrictions on access to information, and not restrictions on its 
"use". The Court shall craft instructions for defining "exceeding authorized access" in 
Specifications 13 and 14 of Charge II using the language in the legislative history in 1996. 

2. Should the Government not prove an element as alleged in the specifications in accordance 
with the instructions given in accordance with the narrow view of Nosal III at the close of the 
evidence, the Court shall entertain motions under R.C.M. 917 or for a finding that the evidence is 
not legally sufficient to sustain a guilty finding. 

RULING: The Defense Motion to dismiss Specifications 13 and 14 of Charge II for failure to 
state an offense is DENIED. 



So ORDERED: this 8 m day of June 2012. 




DENIS E R. LWD 
COL, JA 

Chief Judge, 1st Judicial Circuit 



9 



